CVE-2025-26399: SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
SolarWinds Web Help Desk contain a deserialization of untrusted data vulnerability in AjaxProxy that could allow an attacker to run commands on the host machine.
Other sources
SolarWinds Web Help Desk was found to be susceptible to an unauthenticated AjaxProxy deserialization remote code execution vulnerability that, if exploited, would allow an attacker to run commands on the host machine. This vulnerability is a patch bypass of CVE-2024-28988, which in turn is a patch bypass of CVE-2024-28986.
— MITRE
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
SolarWinds Web Help Desk (AjaxProxy)to a version that resolves this vulnerability.Fixed in 12.8.7 HF1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-26399?
CVE-2025-26399 is considered a critical vulnerability due to its potential for remote code execution.
How can I mitigate CVE-2025-26399?
To mitigate CVE-2025-26399, ensure you apply the latest security patch provided by SolarWinds for Web Help Desk.
What systems are affected by CVE-2025-26399?
CVE-2025-26399 affects SolarWinds Web Help Desk software.
What type of vulnerability is CVE-2025-26399?
CVE-2025-26399 is an unauthenticated AjaxProxy deserialization vulnerability allowing remote code execution.
Is CVE-2025-26399 a new vulnerability?
CVE-2025-26399 is a patch bypass of the previously reported CVE-2024-28988 vulnerability.